Cybersecurity Research

Exposed Cloud Functions: A Growing Entry Point for Attackers

Key Takeaway If your business uses cloud based apps or AI tools built on serverless functions, ensure they require authentication and are regularly checked for vulnerabilities in code and third-party packages.

Security assessments by Mandiant, part of Google Threat Intelligence, have repeatedly found publicly exposed serverless applications that lack authentication. These are often deployed to meet specific business needs, but they run custom code and third-party packages that can be vulnerable to attacks such as local and remote file inclusion. If exploited, attackers can gain control of the underlying container, potentially leading to a full compromise of the victim's cloud environment.

Serverless computing, also known as Function-as-a-Service, lets businesses run small pieces of code without managing servers. It underpins e-commerce, media, payment processing, and increasingly, AI tools like chatbots and automated agents. As generative AI adoption grows, so does reliance on serverless functions, making these environments a more attractive target for attackers.

Once attackers gain access through an exposed function, they often look for ways to escalate their access or move further into the network. This can include extracting secrets stored in application code or examining application logic and data to find additional weaknesses to exploit.

cloud security serverless Google Cloud AI security Mandiant
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Google Threat Intelligence. We link back to every original so you can read it yourself.